Microsoft
91,472 known vulnerabilities
Top Products
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory.
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memo
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking
UniSign 2.0.4.0 and earlier version contains a stack-based buffer overflow vulnerability which can overwrite the stack w
3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation direc
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control"
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially craft
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially craft
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the user mode video driver trace logger com
An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email mess
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain
UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA
Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 al
Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Los
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can
A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a kn
A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user a
A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling xfa.event.rest XFA J
An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a JavaScript Denial of Se
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the repeated release of th
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling certain XFA JavaScri
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the lack of proper validat
An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Memory Corruption due to
An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Heap Corruption due to da
An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a NULL pointer dereferenc
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling the clone function d
A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attac
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started